Description
A prototype pollution attack in cached-path-relative versions <=1.0.1 allows an attacker to inject properties on Object.prototype which are then inherited by all the JS objects through the prototype chain causing a DoS attack.
Remediation
References
https://hackerone.com/reports/390847
https://lists.debian.org/debian-lts-announce/2022/12/msg00006.html
Related Vulnerabilities
CVE-2015-3271 Vulnerability in maven package org.apache.tika:tika-server
CVE-2020-28458 Vulnerability in npm package datatables.net
CVE-2020-15232 Vulnerability in maven package org.mapfish.print:print-lib
CVE-2016-9299 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2023-33510 Vulnerability in maven package org.jeecgframework.p3:jeecg-p3-biz-chat